Tenant-scoped access
Organizations, locations and users remain scoped. Role defaults can be overridden with explicit user permissions while preserving a deny-by-default model.
Carta's foundation is structured for tenant isolation, least privilege, auditable changes and SOC 2 readiness. Readiness is not the same thing as an independent SOC 2 attestation.
Organizations, locations and users remain scoped. Role defaults can be overridden with explicit user permissions while preserving a deny-by-default model.
PostgreSQL row-level security, separate runtime identities and intentionally narrow public functions reduce cross-tenant exposure risk.
Source identity, retrieval timestamp, content hashes and original object references create a durable chain from displayed facts back to evidence.
Public-source fetches are allowlisted and designed to reject private networks, metadata endpoints, unsafe redirects and uncontrolled response sizes.
High-risk actions belong behind explicit permissions and audit records. Arbitrary browser SQL is intentionally excluded from the customer admin surface.
The data model includes access reviews, incidents, evidence and retention controls. Formal compliance still requires operating evidence and an independent audit.